Last updated 2026-09-29. This policy describes exactly what the TradeStar Insider service — the website www.tradestarinsider.com, the REST API at api.tradestarinsider.com, and the MCP server at mcp.tradestarinsider.com/mcp — does with request data. It describes what the code actually does. If any statement here is wrong, it is a bug; report it (see Contact) and it will be fixed.
Each request to the API or MCP server appends one line to a server-side request log. The purpose is strictly operational: keeping the service up, enforcing the per-IP rate limit, and measuring aggregate demand. Each line contains only these fields:
| Field | What it is |
|---|---|
ts | UTC timestamp of the request (to the second). |
surface | Which service handled it: api, mcp, app, or status. |
route | The request path (e.g. /mcp or an API route). Not the query arguments. |
tool | For MCP, the name of the tool called (e.g. insider_cluster_buys) — never its arguments. |
kind | The coarse request type (a real tool call vs. a handshake/discovery message). |
status | The HTTP status code returned. |
ip_hash | A salted hash of your IP address, not the address itself. The salt rotates every day, so the same IP produces a different, non-linkable hash on a different day. Used only to enforce the per-IP daily rate limit. |
consumer | For the RapidAPI paid tier only, the RapidAPI-supplied user identifier that accompanies the request. Absent (null) for direct/free and MCP traffic. |
via | The channel: rapidapi, direct, or internal (our own machinery). |
channel | For MCP, the client name a connector advertises in its handshake (e.g. insider-signals-mcp for the optional local proxy, or a connector name such as Claude or Cursor). To attribute later tool calls in the same session, the server issues a random per-session id on the handshake (an Mcp-Session-Id header) and, for calls that echo it, records the same handshake client name — used only to see which listing brings usage. The value is sanitized before storage: reduced to a short, single-line label (control characters and any URL removed, length capped), and it is never interpreted as an instruction. Absent for a direct MCP client that sends no client name or session id. |
What is not logged: your raw IP address, the arguments/parameters you pass to any tool, request or response bodies, browser fingerprints, and any personal identifier. There is no cross-day tracking — the daily-rotating salt makes the IP hash deliberately un-linkable across calendar days.
The request log lives on the server that runs the service (a single self-hosted origin behind a Cloudflare tunnel). It is not sent to any third-party logging or analytics service. Log files are pruned automatically: entries older than 45 days are deleted, along with the daily salt for those days.
The website, the API, and the MCP server set no cookies. They use no client-side storage, no analytics, and no third-party trackers. There are no accounts to sign in to, so there is no session cookie.
We do not share, rent, or sell request data. But two infrastructure providers necessarily process requests in transit to deliver the service:
We use no other third parties on these surfaces — no analytics, no error-tracking, no ad networks. The underlying data we serve is public information from SEC EDGAR and USAspending.gov; we add no personal data to it.
We do not sell personal data, and there is no personal data in our logs to sell — only salted, daily-rotating IP hashes and coarse operational metadata.
Questions, corrections, or privacy requests: open an issue at github.com/TradestarV5/insider-signals/issues. If you believe any statement in this policy does not match what the service actually does, please report it there so it can be fixed.